On a Tuesday morning your front desk gets a request from a dermatology office: send the last two years of notes, the intake form, and "any photos you have" for a patient your physician referred out last week. The patient was prescribed Soolantra at that visit. Your medical records clerk asks whether she needs a signed authorization before anything leaves the building. The honest answer — no, not for treatment — is the easy part. The hard part is everything that happens after: which system the photos live in, who fulfills the request, what gets logged, and whether the fax line or portal you use is covered by a signed agreement.

This post is about that workflow, not about the drug. Soolantra is a topical prescription commonly used in rosacea management, and rosacea care routinely bounces between primary care and dermatology. That referral pattern is why your practice ends up moving records across organizational lines several times a month. If you administer a practice, run privacy, or sell software to one, the operational questions below are yours.

Do You Need Written Authorization to Send Records for a Soolantra Referral?

No. Under the Privacy Rule, a covered entity may disclose protected health information to another covered entity for the recipient's treatment activities without patient authorization. That is 45 CFR 164.506(c)(2), and HHS has published plain-language guidance on permitted uses and disclosures confirming it. Sending a consult packet to the dermatologist your physician referred to is a treatment disclosure. So is the dermatologist sending the consult note back.

Three follow-on rules your staff should have memorized:

  • Minimum necessary does not apply to treatment disclosures. HHS says so directly in its minimum necessary guidance. You may send the full relevant record to a treating provider. You are not required to redact it into uselessness.
  • State law may be stricter. Some states impose consent requirements on disclosure of substance use, behavioral health, HIV, or minors' records that ride along in the same chart. If your referral packet is an automatic chart export, you need a rule for what gets excluded.
  • Verification is still required. You must reasonably verify the identity and authority of the requester. "A fax that says Dermatology Associates" is not verification if nobody at your practice ever confirmed the number.

What Actually Leaves the Building on a Dermatology Referral

Write the packet contents down as a standing list. When staff improvise, they either over-send or under-send, and both create work.

A typical outbound dermatology referral packet contains the referring note, problem list, current medication list, allergy list, relevant labs, insurance and demographic data, and — this is the one people forget — clinical photographs taken at the primary care visit. A Soolantra prescription usually implies a visual condition was documented, and visual documentation is the item most likely to be sitting somewhere your EHR administrator has never audited.

Assign the packet to a role, not a person

Referral coordinator assembles. Provider or designated clinical staff reviews for state-protected categories. Records clerk transmits and logs. If your practice has one person who does all three, document that consolidation and note the compensating control — usually a second-look review at month end. OCR does not object to small teams. It objects to undocumented ones.

Here is where dermatology-adjacent referrals differ from a cardiology or GI referral. Images of a patient's face are PHI, they are unusually identifiable, and they are captured on devices that were never provisioned by your IT vendor.

Audit this honestly. Ask three questions and accept the uncomfortable answers:

  1. Where was the last clinical photo in your practice taken? If the answer is a personal phone, you have an unmanaged endpoint holding facial PHI, and it is probably backing up to a consumer cloud account.
  2. How did that photo get into the chart? If it was texted, emailed, or AirDropped, name the transport and check whether a business associate agreement covers it.
  3. Was it deleted from the capture device? Most practices assume yes. Most practices are wrong, because the camera roll and the "recently deleted" folder both persist.

The fix is procedural, not technical: a written clinical photography policy that names the approved capture app, prohibits personal-device camera roll storage, requires deletion confirmation at the end of the visit, and specifies who may transmit images externally. If you use a store-and-forward teledermatology platform for the referral, that vendor is a business associate and needs an executed agreement before the first image moves. If you do not have one on file, a signature-ready business associate agreement you can generate and execute the same day closes the gap faster than waiting on the vendor's legal team.

The Pharmacy and Payer Leg

The referral is not the only disclosure a Soolantra encounter triggers. Once the prescription is written, PHI moves to at least two more organizations.

E-prescribing and the pharmacy

Transmission to the dispensing pharmacy is a treatment disclosure. No authorization needed. Your obligation is on the transport side: the e-prescribing network and your EHR vendor are business associates, and their agreements should be current, dated, and stored where you can retrieve them in under five minutes during an audit.

Prior authorization and appeals

Branded topicals frequently require prior authorization, which means clinical documentation goes to the health plan or its pharmacy benefit manager. That is a payment disclosure, also permitted without authorization, but minimum necessary does apply here. Your PA staff should send what the plan's form requires, not the entire chart. A common failure: staff attach the full visit note including unrelated conditions because it is faster than filling in fields. Train against it and spot-check the outbound PA queue quarterly.

Manufacturer copay and savings programs

This one is different and staff get it wrong. Enrolling a patient in a manufacturer-sponsored savings or support program is not treatment and not payment to a covered entity. If your staff transmit patient information to a program administrator on the patient's behalf, get a written authorization, or hand the patient the enrollment materials and let them submit their own information directly. Document which path your practice uses so the answer is consistent across the front desk.

The Return Trip: Getting the Consult Note Back

Referral loops close badly at most practices. The dermatologist sees the patient, prescribes, and the note reaches your referring physician six weeks later or never. That is a care coordination problem first and a records problem second, but it lands on the administrator's desk either way.

Build a tickler. Referral coordinator logs the outbound date, sets a 21-day follow-up, and calls if no consult note has arrived. When it does arrive, it must be indexed to the chart, not left in a scan queue. If the specialist sends via direct secure messaging, confirm your EHR routes those messages to a monitored inbox with a named owner — an unmonitored Direct address is functionally a records black hole, and it will surface during your next access request.

When the Patient Asks for the Records Themselves

Different rule, different clock. A patient exercising the individual right of access gets a response within 30 days, with one 30-day extension available if you notify them in writing of the reason and expected date. HHS maintains detailed right of access guidance, and this has been a sustained enforcement focus — OCR has resolved a long series of access initiative cases against practices of every size, most of them small, most of them for delays rather than refusals.

Two specifics that bite dermatology-adjacent practices:

  • Photographs are part of the designated record set if they were used to make care decisions. "We only release the notes" is not a defensible position.
  • The patient may direct the copy to a third party in a signed, written request identifying the recipient and delivery method. Your staff should recognize that request type and not route it into the authorization pile where it will sit for two weeks.

A Ten-Day Worked Timeline

Here is what a clean Soolantra referral looks like when the workflow is written down:

  • Day 0. Visit. Photos captured on the approved app, verified as uploaded to the chart, deleted from the device. Prescription transmitted. Referral order entered.
  • Day 1. Referral coordinator assembles the packet, clinical reviewer screens for state-protected content, packet transmitted through the logged channel. Disclosure logged with date, recipient, and contents.
  • Day 2–4. Prior authorization submitted if required, using the plan's form fields only. PA submission logged.
  • Day 21. Tickler fires. No consult note? Coordinator calls the specialist's records line.
  • On receipt. Consult note indexed to the chart, referring physician notified in the EHR, loop marked closed.

Every step above has an owner, a log entry, and a trigger. That is the whole discipline.

Turn the Workflow Into Documentation Before Anyone Asks

A referral pathway like this touches your EHR, your imaging or teledermatology platform, your e-prescribing network, your fax or secure messaging service, your clearinghouse, and possibly a transcription vendor. Each is a business associate. Each belongs on a maintained inventory with a current agreement, and each belongs in your Security Rule risk analysis — which is not a one-time project but an ongoing obligation, and the single most common finding in OCR resolution agreements year after year. You can review the public record yourself on the HHS breach portal; the pattern of vendor-involved and unencrypted-device incidents is not subtle.

If your risk analysis is a spreadsheet last updated by someone who left in 2023, that is the gap to close first. Tools that automate HIPAA risk analysis reports, policies, and the supporting document set get you to a defensible baseline in days rather than months, and they keep the artifacts versioned so you are not reconstructing history under deadline. No product — this one included — is government-certified; HHS does not certify or endorse compliance software. What good tooling gives you is the documentation trail, which is exactly what an investigator asks for.

Your Next Move

Pull the last five referrals your practice sent to dermatology. Check whether each has a logged disclosure, a confirmed transport channel with an executed BAA, and a closed loop with a received consult note. If any of the three is missing, you have found your next policy revision. Start by generating a current risk analysis and the policy set that supports it, then map this referral workflow into it while the details are fresh.